Impact
A missing authorization check in the Rank Math SEO WordPress plugin allows users with the Author role and higher to read the title, body, and SEO metadata of other users’ unpublished posts. The vulnerability stems from an insufficient access control validation when the API endpoint processes post requests, leading to a disclosure of confidential content that should remain private. This is a classic improper authorization flaw (CWE-639).
Affected Systems
The vulnerability affects the Rank Math SEO plugin for WordPress versions prior to 1.0.277, regardless of the vendor name provided in the CNA data. Only installations running those earlier releases are vulnerable.
Risk and Exploitability
The CVSS score is 2.7, indicating a low severity information disclosure. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalogue. Attackers can trigger the flaw by accessing the plugin’s abilities API, which is reachable to any logged‑in user with Author or higher capabilities. The potential impact involves confidentiality disclosure of content that should be viewable only to its author or administrators, making the risk significant for organizations that handle sensitive unpublished material.
OpenCVE Enrichment